Description
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The DLL Services component in Mozilla Firefox can be abused to obtain privileges beyond those originally granted, enabling an attacker to perform privileged actions that compromise the integrity, confidentiality, and availability of the system. The weakness is fundamentally an improper privilege management flaw, specifically a privilege escalation scenario that allows lower-level processes or code to elevate their rights.

Affected Systems

This vulnerability affects Mozilla Firefox across both Extended Support Release (ESR) and regular versions. It was confirmed to have been fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. All releases older than these specific builds remain vulnerable.

Risk and Exploitability

The CVSS score of 8.8 classifies this vulnerability as high severity, while EPSS data is not available, leaving exploitation probability unknown. The flaw does not appear in the CISA KEV catalog, so no confirmed public exploitation has been reported. The likely attack vector, inferred from the nature of DLL Services, would involve local execution or manipulation of DLL loading to inject malicious code, although the precise conditions are not detailed in the description.

Generated by OpenCVE AI on September 30, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox ESR 153.4 or later
  • Upgrade to Mozilla Firefox 157 or later
  • Upgrade to Mozilla Firefox ESR 140.17 or later

Generated by OpenCVE AI on September 30, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 29 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Title Privilege escalation in the DLL Services component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-30T03:56:08.425Z

Reserved: 2026-09-26T19:17:46.301Z

Link: CVE-2026-100801

cve-icon Vulnrichment

Updated: 2026-09-29T13:36:13.097Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T13:17:45.180

Modified: 2026-09-30T04:18:14.087

Link: CVE-2026-100801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management